Chrome extension privacy policy
How the Siyasati extension handles your data
This policy explains what the extension reads when you activate it, what remains in your browser, and what is sent to Siyasati servers to provide the workspace, analysis, and report.
Effective date: September 22, 2026
At a glance
- The extension works without an email address or password, but creates an installation identity for this browser.
- It reads the active page only when you activate it or request a policy capture, and it does not build a browsing history.
- Store details and policy text are sent to Siyasati when you choose to save or analyze them.
- Server workspace records currently have no automatic deletion schedule, and uninstalling the extension does not delete them.
Publisher and scope
Siyasati publishes this extension as part of BandAI. The published contact location is Riyadh, Saudi Arabia. This policy covers “سياساتي | Siyasati” and the server services used by the extension.
This page does not cover other Siyasati products or the websites and stores you open in the browser; those services have their own policies.
Website content the extension reads
The extension uses active-tab access when you click its icon. It may read text you selected or visible text within a recognized policy area, together with the page title and URL after query parameters and fragments are removed.
It may also extract the public store name, platform, URL, and links to privacy, terms, returns, and shipping policies. Review captured text before saving it because automated extraction may include unintended content.
The extension does not run in the background to collect browsing history and does not request the Chrome history permission. Its access to website content follows an action you initiate on the active page.
Data stored in your browser
The extension generates a random installation ID and secret and stores them in Chrome local storage restricted to trusted extension contexts. They allow this installation to reopen the same workspace without a conventional account.
It stores the access session, page capture, store discovery, and temporary drafts in extension session storage. It also stores active-analysis state locally so it can resume showing progress. Your interface language and guide-display preferences are also stored locally inside the extension.
Clearing extension data or uninstalling removes this local data and may prevent you from proving the link to the previous workspace, but it does not send a deletion request to the server.
Data stored by Siyasati
When you begin, the extension sends the installation ID and secret over HTTPS. The server derives a cryptographic digest and creates an internally pseudonymous workspace record. This is not fully anonymous because workspace data remains linked to the same internal identifier.
When you choose to save, we store the store URL, name, business activity, platform, Saudi-market confirmation, policy type and text, source URL, revisions, and review actions such as approval or copy.
When you request analysis, we store the scan input, status, task identifiers, and result, including the score, findings, suggestions, and improvements. The HTML report is generated in the extension from the results it received; downloading it does not separately transmit the report content.
Why we use this data
We use this data to provide the extension features you request and keep each operation connected to your workspace.
- Recognize the workspace and issue a short-lived access session without a conventional account.
- Capture, save, restore, and version store policies for review.
- Analyze policy text, display sourced results and recommendations, and generate a downloadable report.
- Resume in-progress scans, prevent duplicate submissions, handle errors, and support service security and reliability.
Processing by service providers
Hostinger hosts the Siyasati server and its databases. For analysis, Siyasati sends its policy-analysis service the store name, business activity, policy type and text, and technical task identifiers.
The analysis service sends policy content and analysis instructions through our AI gateway to OpenAI, the AI provider configured for the service at the date of this policy. Analysis therefore involves processing by an external AI provider, not only by Siyasati.
The analysis service separately stores copies of the submitted policy text and analysis results, task status, and technical usage records. These copies are separate from the records saved in your Siyasati workspace.
Where data is stored and processed
Browser data is stored in the Chrome profile on your device. Workspace records are stored in a PostgreSQL database on our Hostinger server; the analysis service stores input and result copies in a separate MongoDB database on that server.
Our Hostinger server is located in Paris, France, outside Saudi Arabia. This is where the workspace database and the analysis service’s separate database are hosted. Our published contact address in Riyadh is not the hosting location.
Content sent to OpenAI may be processed outside Saudi Arabia. We have not verified a Saudi-only processing arrangement or a specific processing country for this connection. Provider-side retention is separate from storage in your browser and our databases.
Operational logs and security
The service API and hosting infrastructure may create operational logs needed to operate, secure, and diagnose the service, such as IP address, request time, HTTP method and path, status code, client software information, response time, and error messages. The extension does not create a separate browsing-history log.
The extension transmits data to api.siyasati.com over HTTPS. Durable local storage is restricted to trusted extension contexts, and the extension does not request permanent access to every website. No technical method can guarantee absolute security.
Retention and deletion
There is currently no fixed retention period or automatic deletion schedule for workspace records, store details, policy text and revisions, scans, or results. The analysis service also retains input and result copies; expiry of some temporary caches does not delete those records.
Uninstalling the extension or clearing browser data does not delete server records. Cancelling an analysis is not a deletion request. The extension does not currently provide self-service deletion.
Deletion of workspace records alone does not remove the separate analysis-service copies. A deletion request must account for both systems and any relevant provider-held copies. We have not established a fixed deletion completion time or a verified retention period covering operational logs and backups.
Access, correction, and deletion requests
You may contact us to request access to, correction of, or deletion of workspace data. Because the extension does not collect your email address and does not currently provide a self-service deletion button, we must verify that a request is connected to the relevant workspace or store before acting.
Include the store URL, the approximate workspace creation date, and any workspace identifier visible to you. Do not email the installation secret, access token, or full policy text. If we cannot securely associate the request with the workspace, that may limit our ability to perform the request.
If you email us, we receive your email address and the information you include so we can review and respond to your request. Please contact us before removing the extension, because losing its installation identity can make workspace verification harder.
Chrome Web Store Limited Use disclosure
Siyasati’s use and transfer of information received through the Siyasati Chrome extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
We use Chrome permissions and website data the user chooses to share only to provide and support the extension’s visible purpose: capturing, saving, analyzing, reviewing, and reporting on store policies.
We do not sell extension user data or use it for targeted advertising.
Personnel may access user data only when the user has given specific consent for support, when access is needed for security, or when required by law.
Updates and contact
We may update this policy when the extension or its data handling changes. We will post the updated version and effective date on this page.
For questions about privacy or Siyasati extension data, contact the published email address below.